“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
UAT-8837 Critical Infrastructure Attack
What is the Attack? An active campaign has been linked, with medium confidence, to a threat actor designated UAT-8837, which Cisco Talos assesses as a China-nexus group targeting critical infrastructure organizations in North America. Observed activity includes targeted intrusions aimed at gaining initial access, credential harvesting, and internal reconnaissance. UAT-8837 primarily gains initial access by…
-

OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans [email protected] (The Hacker News)
OpenAI on Friday said it would start showing ads in ChatGPT to logged-in adult U.S. users in both the free and ChatGPT Go tiers in the coming weeks, as the artificial intelligence (AI) company expanded access to its low-cost subscription globally. “You need to know that your data and conversations are protected and never sold…
-

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection [email protected] (The Hacker News)
The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that’s designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives. “The actor creates a malformed archive as an anti-analysis technique,” Expel security researcher Aaron Walton said in a report shared with The Hacker News. “That…
-

Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts [email protected] (The Hacker News)
Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that masquerade as human resources (HR) and enterprise resource planning (ERP) platforms like Workday, NetSuite, and SuccessFactors to take control of victim accounts. “The extensions work in concert to steal authentication tokens, block incident response capabilities, and enable complete accountRead More
-
News brief: Security flaws put thousands of systems at risk
Check out the latest security news from the Informa TechTarget team.Read More
-

Your Digital Footprint Can Lead Right to Your Front Door [email protected] (The Hacker News)
You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media. But what about the information about you that’s already out there—without your permission? Your name. Home address. Phone number. Past jobs. Family members. Old usernames. It’s all still online, and it’s a lot easier to…
-

LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing [email protected] (The Hacker News)
Security experts have disclosed details of a new campaign that has targeted U.S. government and policy entities using politically themed lures to deliver a backdoor known as LOTUSLITE. The targeted malware campaign leverages decoys related to the recent geopolitical developments between the U.S. and Venezuela to distribute a ZIP archive (“US now deciding what’s next…
-

China-Linked APT Exploits Sitecore Zero-Day in Attacks on American Critical Infrastructure [email protected] (The Hacker News)
A threat actor likely aligned with China has been observed targeting critical infrastructure sectors in North America since at least last year. Cisco Talos, which is tracking the activity under the name UAT-8837, assessed it to be a China-nexus advanced persistent threat (APT) actor with medium confidence based on tactical overlaps with other campaigns mounted…
-

Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways [email protected] (The Hacker News)
Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, nearly a month after the company disclosed that it had been exploited as a zero-day by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686. The vulnerability, tracked…
-

AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks [email protected] (The Hacker News)
A critical misconfiguration in Amazon Web Services (AWS) CodeBuild could have allowed complete takeover of the cloud service provider’s own GitHub repositories, including its AWS JavaScript SDK, putting every AWS environment at risk. The vulnerability has been codenamed CodeBreach by cloud security company Wiz. The issue was fixed by AWS in September 2025 following responsible…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
